Live data from Hacker News

The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

bloomberg.com

191–200 of 818 posts

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#191

Earlier quoted context omitted.

Assuming Bloomberg's story is true, I wonder what reason Apple has to hide. Not wanting to upset relations with the PRC govt?

This article is more or less total bullshit. At _best_ that device might be a mechanism to cause failure intentionally. And there are tons of ways to detect it with commodity technology, and plenty of vendors who implement that technology for assembly manufactures commercially.

That’s what I thought but then it says it’s hooked to the BMC bus. It’s basically a small IME device with no java bloatware to run. I’d think it’s reasonably credible

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#193
post #77

Earlier quoted context omitted.

First, wow this is both incredible and crazy! Both the China-side hacks and your side's anti-hack. Mind. Blown. Second, would have it been cheaper to manufacture somewhere more trustworthy (another country?) instead of spending all this time/money on your anti-hack systems?

> Second, would have it been cheaper to manufacture somewhere more trustworthy (another country?) instead of spending all this time/money on your anti-hack systems? I'd like to know this too. Has the West completely lost the ability to mass produce microchips at even a reasonable cost for financial applications?

Offshoring has its costs.

It's the unknown unknowns that get you.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#194

Earlier quoted context omitted.

SuperMicro hardware has very extensive IPMI integration into the mothebroard, which amongst other things can take over and inject frames into the network interface, emulate a VGA device, talk to the CPUs serial lines directly, flash firmware, control the state of a number of physical devices- and this is what it supports just from the web interface it presents by default with the password "ADMIN:ADMIN". My money, bas…

But without the IPMI kernel modules loaded, IPMI is harmless, right ?

No, the controller runs it's own totally separate OS, has connections to most/all the buses and is able to emulate devices whether you have drivers installed or not.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#195

Earlier quoted context omitted.

they have literally every reason to deny and literally no reason to say it's true

Except, you know, to avoid committing securities fraud by making a material misrepresentation.

There is no way that the intelligence community would allow that fraud case to go ahead.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#196
post #178

Earlier quoted context omitted.

> as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag You didn’t specify what type of anti-tamper was used, but I wanted to jump in and say usually that means nothing. The US government intercepted packages [0] and put in back doors (removing and replacing the seals), so I’m not sure why you were so quick…

You can just buy counterfeit anti-tamper stickers but if there is a switch inside the unit that flips a bit in some sort of write-once memory, then that would require removal of an entire chip and replacing it with another that may not be 100% the same. You can have a chain of trust in the system where chips will only talk to each other if they all spit out the right hash. Bury the SPI/I2C lines you use for this trus…

The device outer enclosure was tamper evident but the device itself was tamper proof HSM, basically. Any kind of intrusion (melting, dissolving, drilling, etc.) into a secure internal enclosure (separate processor, memory and battery) would cause internal battery to be disconnected from internal SRAM and basically the device would loose all cryptographic material and then self-destruct.

To give a bit of background, when you type your PIN on credit card terminal it is not the terminal application that is really getting the pin (well, except for special credit cards but that is really problem of the Bank that issued the card). The Visa/Mastercard mandate that the application don't have control over the PIN and that the PIN entry uses physically separate keyboard and display.

To achieve this, the keyboard and the display is galvanically separated for the duration of the PIN entry and the PIN is transferred directly to the HSM where it is being encrypted before it is transferred to the application processor for the rest of processing.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#197
post #110
post #74

I have worked in card payment industry. We would be getting products from China with added boards to beam credit card information. This wasn't state-sponsored attack. Devices were modified while on production line (most likely by bribed employees) as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag. Once…

Why don't you guys consider to expose this by suing the bad manufacturer? I believe this could help other truely honest manufacturers both in and outside China to beat the wrong doers.

The Chinese operation would simply shut down and reopen under a different name. And the credit card companies are always very worried about their brand image, so they are not interested in any negative publicity.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#198
post #170

Earlier quoted context omitted.

> as once they were closed they would have anti-tampering mechanism activated so that later it would not be possible to open the device without setting the tamper flag You didn’t specify what type of anti-tamper was used, but I wanted to jump in and say usually that means nothing. The US government intercepted packages [0] and put in back doors (removing and replacing the seals), so I’m not sure why you were so quick…

The chinese government is probably not interested enough in credit card numbers to warrant involvement.

It would be foolish to show your hand for few pennies.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#199
post #142

Earlier quoted context omitted.

Assuming Bloomberg's story is true, I wonder what reason Apple has to hide. Not wanting to upset relations with the PRC govt?

NSL letter, under active investigation

NSLs require secrecy not lying.

Re: The Big Hack: How China Used a Tiny Chip to Infiltrate Amazon and Apple

#200
post #178

Earlier quoted context omitted.

You can just buy counterfeit anti-tamper stickers but if there is a switch inside the unit that flips a bit in some sort of write-once memory, then that would require removal of an entire chip and replacing it with another that may not be 100% the same. You can have a chain of trust in the system where chips will only talk to each other if they all spit out the right hash. Bury the SPI/I2C lines you use for this trus…

The device outer enclosure was tamper evident but the device itself was tamper proof HSM, basically. Any kind of intrusion (melting, dissolving, drilling, etc.) into a secure internal enclosure (separate processor, memory and battery) would cause internal battery to be disconnected from internal SRAM and basically the device would loose all cryptographic material and then self-destruct. To give a bit of background, w…

Those VISA/MasterCard rules can't be universal because there's at least one bank issuing merchant terminals that run Android and take the PIN on the touchscreen:

https://www.commbank.com.au/business/merchant-services/eftpo...

Post reply on HN